Core Lightning has fixed a vulnerability in version v26.06.7 that could allow peers to broadcast old, revoked channel states without triggering a cheating penalty. This vulnerability requires specific channel settings to be exploited, where a peer that did not specify a pre-close script when opening a channel could name a revoked commitment's output script in the close message, thereby bypassing the penalty mechanism. The project strongly recommends users upgrade to version v26.06.8, as some v26.06.7 Docker images released between August 28 and September 1, while showing as updated, actually lack the fix.